CVE-2026-62832
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| microsoft | windows 10 21h2 | < 10.0.19044.7663 |
| microsoft | windows 10 22h2 | < 10.0.19045.7663 |
| microsoft | windows 11 23h2 | < 10.0.22631.7517 |
| microsoft | windows 11 24h2 | < 10.0.26100.9168 |
| microsoft | windows 11 25h2 | < 10.0.26200.9168 |
| microsoft | windows 11 26h1 | < 10.0.28000.2704 |
| microsoft | windows server 2022 | < 10.0.20348.5499 |
| microsoft | windows server 2025 | < 10.0.26100.33296 |
Related articles
VulnerabilitiesMicrosoft Fixes 421 Vulnerabilities, Including an Exploited Zero-Day in `afd.sys`
On August 11, 2026, Microsoft released security updates addressing 421 vulnerabilities. One of them is CVE-2026-68820 , a high-severity flaw actively
VulnerabilitiesShieldBreak: PoC Bypasses Microsoft Defender Patch and Targets SYSTEM Privileges
ShieldBreak PoC bypasses MS Defender patch for CVE-2026-50656, granting SYSTEM access. Tested on Win11 25H2 & Server 2025. Update systems promptly.
VulnerabilitiesMicrosoft Fixes “LegacyHive” Windows Zero-Day with August Patches
Microsoft patches LegacyHive zero-day CVE-2026-62832 in August updates, fixing privilege escalation in Windows User Profile Service. Apply now.
VulnerabilitiesMicrosoft Fixes 398 Vulnerabilities as Exploited Windows Kernel Flaw Enters CISA KEV
Microsoft patched 398 vulnerabilities, including exploited Windows kernel flaw CVE-2026-68820 now in CISA KEV. Patch immediately.
This product uses the NVD API but is not endorsed or certified by the NVD.